Alarm processing method and device based on custom rule and electronic equipment

Through custom rules to identify root cause and secondary alarms, combined with cache conditions and two-way scanning mechanism, the error convergence or misconvergence caused by dynamic changes in the association relationship of alarm events in the existing technology is solved, and efficient alarm processing and management is achieved.

CN120342840APending Publication Date: 2025-07-18太保科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510544707.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

When handling massive alarm events, the existing technology fails to effectively consider the dynamic changes in the correlation between different alarm events, resulting in misconvergence or misconvergence, affecting the accuracy and reliability of operation and maintenance personnel for business failures.

Method used

Custom rules are used to identify root cause alarms and secondary alarms, combined with cache conditions and two-way scanning mechanism, and accurately identify and converge alarm events through the correlation terms of root cause rules and secondary rules.

Benefits of technology

It improves the accuracy and reliability of alarm processing, reduces the development work and learning costs of operation and maintenance personnel, and enhances the flexibility and convenience of alarm management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342840A_ABST
    Figure CN120342840A_ABST
Patent Text Reader

Abstract

The invention provides an alarm processing method and device based on a custom rule and electronic equipment. The method comprises the steps that a target alarm rule is acquired, the target alarm rule is generated by user-defined configuration of a target device needing to be monitored by a user, the target alarm rule comprises a root cause rule used for identifying a root cause alarm and a secondary rule used for identifying a secondary alarm, and the secondary rule has an association item of the root cause rule; acquiring an alarm event generated by the target equipment, and identifying the alarm event according to a root cause rule to judge whether the alarm event is a root cause alarm; if yes, storing the alarm event as a root cause alarm, extracting an assignment of an associated item in the root cause alarm, and identifying each cache event one by one according to a secondary rule and the assignment of the associated item to judge whether a secondary alarm associated with the root cause alarm can be extracted from each cache event; the cache event refers to an event which meets a preset cache condition and occurs earlier than the alarm event; and otherwise, judging whether the alarm event is a secondary alarm or not according to the cache condition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application mainly relates to the field of computer alarm technologies, and particularly relates to an alarm processing method, apparatus, and electronic device based on custom rules. Background Art

[0002] During the use of a business system, operation and maintenance personnel often need to process a large number of alarm events. For example, they converge multiple mutually related alarm events generated by the same device within a short period of time to quickly and accurately determine whether the business system has a fault. Generally speaking, operation and maintenance personnel will adopt some predefined strategies. For example, they converge a large number of alarm events based on the type, severity, occurrence time, device information, etc. of the alarm events. However, this method does not well consider the dynamic changes in the association relationships between different alarm events, and may cause some unrelated alarm events to be wrongly converged together, thus affecting the accuracy and reliability of operation and maintenance personnel in grasping business faults. Summary of the Invention

[0003] The purpose of this application is to provide an alarm processing method, apparatus, and electronic device based on custom rules to improve the accuracy and reliability of alarm convergence.

[0004] In a first aspect, an alarm processing method based on custom rules is provided, including:

[0005] Obtain a target alarm rule, where the target alarm rule is custom-configured by a user for a target device to be monitored, and the target alarm rule includes: a root cause rule for identifying a root cause alarm and a secondary rule for identifying a secondary alarm, and the secondary rule has an associated item of the root cause rule;

[0006] Obtain the alarm events that occur to the target device, and identify the alarm events according to the root cause rule to determine whether it is the root cause alarm;

[0007] If so, save the alarm event as the root cause alarm, extract the assignment of the associated item in the root cause alarm, and identify each cached event one by one according to the secondary rule and the assignment of the associated item to determine whether a secondary alarm associated with the root cause alarm can be extracted from the cached events, where the cached event refers to an event that meets a preset caching condition and occurs earlier than the alarm event;

[0008] Otherwise, determine whether the alarm event is the secondary alarm according to the caching condition.

[0009] In some embodiments, the associated item includes a root cause association attribute, a secondary association attribute, and a comparator configured by the user;

[0010] Wherein, the root cause associated attribute refers to the alarm attribute configured by the user in the root cause rule, the secondary associated attribute refers to the alarm attribute configured by the user in the secondary rule, and the comparator is used to indicate the convergence logic relationship that needs to be satisfied between the root cause associated attribute and the secondary associated attribute.

[0011] In some embodiments, determining whether the alarm event is the secondary alarm according to the cache condition includes:

[0012] If the cache condition is satisfied, the alarm event is matched one by one with each saved root cause alarm to determine whether there is a target root cause alarm that matches the alarm event, where the alarm event conforms to the root cause rule corresponding to the target root cause alarm;

[0013] If so, save the alarm event as the secondary alarm associated with the target root cause alarm;

[0014] Otherwise, extract the assignment of the associated item in each saved root cause alarm, and cache the assignment of the associated item in each saved root cause alarm;

[0015] If the cache condition is not satisfied, wait to execute the alarm event.

[0016] In some embodiments, it further includes:

[0017] In response to the user's instruction to recover the alarm event, determine whether the alarm event is the root cause alarm;

[0018] If so, recover the alarm event as the root cause alarm, and match the alarm event one by one with each saved secondary alarm to determine whether there is a target secondary alarm that matches the alarm event, and then convert the target secondary alarm into the cache event, where the target secondary alarm conforms to the root cause rule corresponding to the alarm event;

[0019] Otherwise, recover the alarm event as the secondary alarm, or convert the alarm event into the cache event.

[0020] In some embodiments, it further includes:

[0021] Poll the cache event using a timer; during the polling process:

[0022] In response to the current cache time of the cache event exceeding the cache time window, convert the cache event into an abnormal event to wait for execution, where the cache time window is determined by the cache condition.

[0023] In some embodiments, it further includes:

[0024] Open a ticket for the root cause alarm trigger; and,

[0025] Open a ticket for the abnormal event trigger.

[0026] In a second aspect, there is provided an alarm processing device based on custom rules, including:

[0027] A rule acquisition module, configured to acquire a target alarm rule, where the target alarm rule is custom-configured by a user for a target device to be monitored, and the target alarm rule includes: a root cause rule for identifying a root cause alarm and a secondary rule for identifying a secondary alarm, and the secondary rule has an associated item of the root cause rule;

[0028] An alarm convergence module, configured to acquire an alarm event that occurs to the target device, identify the alarm event according to the root cause rule to determine whether it is the root cause alarm; if so, save the alarm event as the root cause alarm, extract the assignment of the associated item in the root cause alarm, and identify each cached event one by one according to the secondary rule and the assignment of the associated item to determine whether a secondary alarm associated with the root cause alarm can be extracted from the cached events, where the cached event refers to an event that satisfies a preset cache condition and occurs earlier than the alarm event; otherwise, determine whether the alarm event is the secondary alarm according to the cache condition.

[0029] In a third aspect, there is provided an electronic device. The electronic device includes: one or more processors; and one or more memories coupled to the one or more processors and storing instructions thereon. When the instructions are executed by the one or more processors alone or jointly, the electronic device executes the method in the first aspect above.

[0030] In a fourth aspect, there is provided a non-transitory computer-readable storage medium storing machine-executable instructions. When the machine-executable instructions are executed by one or more processors of the machine, the machine executes any one of the methods above.

[0031] In a fifth aspect, there is provided a computer program product including machine-executable instructions. When the machine-executable instructions are executed by one or more processors of the machine, the machine executes any one of the methods above.

[0032] Compared with the prior art, the present application has the following advantages:

[0033] 1) The alarm handling method based on custom rules provided by this application realizes the separate identification of root cause alarms and secondary alarms through the defined root cause rules and secondary rules, and then combines the cache conditions and the two-way scanning mechanism to achieve timing fault tolerance, thereby improving the accuracy and reliability of alarm handling and helping operation and maintenance personnel accurately diagnose system failures.

[0034] 2) The alarm handling method based on custom rules provided by this application provides an associated item of the root cause rule for the secondary rule, which can accurately associate the secondary alarms that need to be converged with the root cause alarms, improving the reliability of alarm convergence. Moreover, the target alarm rule allows users to generate custom configurations for the target devices to be monitored. Operation and maintenance personnel do not need to rely on complex development work or write script programs, reducing the usage and learning costs.

[0035] 3) The alarm handling method based on custom rules provided by this application also provides a recovery processing mechanism. When an alarm event needs to be recovered, it can automatically reconstruct the convergence relationship between the root cause alarm and the secondary alarm, improving the flexibility and convenience of alarm management.

[0036] It should be understood that the content of the invention is not used to identify the key or basic features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Through the following description, other features of the present disclosure will become easily understandable. Brief Description of the Drawings

[0037] Including the drawings is to provide a further understanding of this application. They are incorporated and constitute a part of this application. The drawings illustrate the embodiments of this application and, together with this specification, serve to explain the principles of this application. In the drawings:

[0038] Figure 1 is a flowchart of an alarm handling method based on custom rules exemplarily provided by this application;

[0039] Figure 2 is a flowchart for determining whether an alarm event is a secondary alarm

[0040] Figure 3 is a schematic diagram of the recovery processing mechanism exemplarily provided by this application;

[0041] Figure 4 is a schematic diagram of an alarm handling device based on custom rules exemplarily provided by this application;

[0042] Figure 5 is a schematic diagram of an electronic device exemplarily provided by this application. Detailed Description of the Embodiments

[0043] The principles of the present disclosure will now be described with reference to some embodiments. It should be understood that the description of these embodiments is for illustrative purposes only and helps those skilled in the art to understand and implement the present disclosure, without imposing any limitation on the scope of the present disclosure. The disclosure described herein can be implemented in a different manner than that described below.

[0044] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains.

[0045] References in this disclosure to "one embodiment", "an embodiment", "exemplary embodiment", etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but not necessarily every embodiment includes the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in connection with an exemplary embodiment, whether or not explicitly described, those skilled in the art will appreciate such feature, structure, or characteristic in connection with other embodiments.

[0046] It should be understood that although terms such as "first" and "second" may be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. The term "and / or" used herein includes any and all combinations of one or more of the listed terms.

[0047] The terms used herein are only for the purpose of describing particular embodiments and are not intended to be limiting of the exemplary embodiments. The singular forms "a", "an", and "the" used herein also include the plural forms unless the context clearly indicates otherwise. The term "a set of elements" or "a collection of elements" as used herein is intended to include one or more elements. It should also be understood that the terms "comprises", "comprising", "has", "having", "includes", and / or "including", when used herein, specify the presence of the described features, elements, and / or components, etc., but do not preclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0048] Figure 1 FIG. 100 is a flowchart of an alarm processing method based on custom rules exemplarily provided by this application, including:

[0049] S101, obtaining a target alarm rule, where the target alarm rule is generated by a user's custom configuration for a target device to be monitored, and the target alarm rule includes: a root cause rule for identifying a root cause alarm and a secondary rule for identifying a secondary alarm, and the secondary rule has an associated item of the root cause rule.

[0050] The root cause rule and the secondary rule can be conditional rules generated by user-defined configuration. Specifically, a conditional rule usually consists of a comparison operator, an alarm attribute name, and an alarm attribute value. An example of a conditional rule is given below:

[0051]

[0052] It will be understood that in the present application, the root cause rule and the secondary rule can consist of only one condition shown above, and it is also supported to be composed of multiple nested conditional rules. The multiple nested conditional rules can be connected by correlation factors (such as "and", "or") to meet more complex trigger logics, and the present application does not limit this.

[0053] In this embodiment, the associated items include the root cause associated attribute, the secondary associated attribute, and the comparison operator configured by the user.

[0054] Among them, the root cause associated attribute refers to the alarm attribute configured by the user in the root cause rule, such as the IP attribute.

[0055] The secondary associated attribute refers to the alarm attribute configured by the user in the secondary rule, such as the host attribute.

[0056] The comparison operator is used to indicate the convergence logic relationship that needs to be satisfied between the root cause associated attribute and the secondary associated attribute, such as equal to, not equal to, contains, does not contain, starts with, does not start with, ends with, does not end with, empty, non-empty, regular, etc., to meet common judgment and comparison.

[0057] Since the root cause associated attribute and the secondary associated attribute have been configured in the root cause rule and the secondary rule, the associated item in the form of a variable can accurately reflect the association relationship between the root cause alarm and the secondary alarm. In the subsequent processing, only by assigning values to the associated item can the secondary alarm be accurately identified, thus avoiding problems such as mis-convergence or missed convergence caused by inaccurate setting of association conditions in the traditional technology.

[0058] An example of the associated item in a secondary rule is given below:

[0059] {

[0060] "op":"eq",

[0061] "value":[" <ip>"],

[0062] "parameter": "host"

[0063] }

[0064] Among the above - mentioned associated items, the root - cause associated attribute is "ip", the secondary associated attribute is "host", and the comparison operator is "eq". Among them, " <ip>"Assign values to the root cause related attributes. In this way, the specific meaning of this association item is: when the host alarm attribute of the secondary alarm is the same as the ip alarm attribute of the root cause alarm, the corresponding root cause alarm and secondary alarm need to be converged.

[0065] S102, obtain the alarm events occurring in the target device, and identify the alarm events according to the root cause rules to determine whether they are root cause alarms.

[0066] According to whether the alarm event conforms to the root cause rules, it can be judged whether the current alarm event is a root cause alarm.

[0067] In other words, if the alarm event conforms to the root cause rules, then it can be determined as a root cause alarm, and finally step S103 is executed; if the alarm event does not conform to the root cause rules, then it is not a root cause alarm, and then step S104 is executed.

[0068] S103, save the alarm event as a root cause alarm, extract the assignment of the association item in the root cause alarm, and identify each cached event one by one according to the secondary rules and the assignment of the association item to determine whether a secondary alarm associated with the root cause alarm can be extracted from each cached event. The cached event refers to an event that meets the preset caching conditions and occurs earlier than the alarm event.

[0069] The caching condition is used to cache the occurred alarm events within a certain time window to avoid misjudgment of the convergence relationship caused by timing errors. In other words, the caching condition is used to indicate the caching time window for which the alarm event needs to be cached. Within the caching time window, the alarm event waits to confirm the alarm relationship with other events. If it exceeds the caching time window, the caching status of the alarm event is released.

[0070] S104, judge whether the alarm event is a secondary alarm according to the caching condition.

[0071] Based on the above method, the alarm processing method based on custom rules provided by this application can accurately identify the secondary alarms that need to be converged by the root cause alarm through the caching condition and the assignment of the association item when the alarm event conforms to the root cause rules. And when the alarm event does not conform to the root cause rules, the alarm event may be a secondary alarm.

[0072] Figure 2 It is a flowchart 200 for judging whether an alarm event is a secondary alarm exemplarily provided by this application. Refer to Figure 2 , in some embodiments, for step S104, it specifically includes:

[0073] S1041, determine whether the alarm event meets the cache condition. If the alarm event meets the cache condition, then execute step S1042, if the alarm event does not meet the cache condition, then execute step S1043.

[0074] S1042, matching the alarm event with each of the saved root cause alarms one by one to determine whether there is a target root cause alarm that successfully matches the alarm event.

[0075] Among them, the alarm event meets the root cause rule corresponding to the target root cause alarm.

[0076] Among them, for S1042, if there is a target root cause alarm that successfully matches the alarm event, then S10421 is executed; if there is no target root cause alarm that successfully matches the alarm event, then S10422 is executed.

[0077] S10421: Save the alarm event as a secondary alarm associated with the target root cause alarm.

[0078] S10422, extract the value assignments of the associated items in each saved root cause alarm, and cache the value assignments of the associated items in each saved root cause alarm.

[0079] S1043, waiting for the execution of an alarm event.

[0080] Based on the above method, the alarm processing method based on custom rules provided by the present application, when the alarm event does not comply with the root cause rule, determines whether the alarm event is a secondary alarm by caching conditions and matching the saved root cause alarms. In other words, it identifies the root cause alarm to which the secondary alarm needs to converge, thereby achieving timing fault tolerance and improving the accuracy and reliability of alarm processing.

[0081] Furthermore, this application also provides a recovery processing mechanism to help operation and maintenance personnel manage alarm events more conveniently. Figure 3 FIG. 3 is a schematic diagram 300 of a recovery processing mechanism provided by the present application. Figure 3 , the alarm processing method also includes:

[0082] S1044, in response to the user's instruction to restore the alarm event, determine whether the alarm event is a root cause alarm. If the alarm event is a root cause alarm, execute step S1045, otherwise, execute step S1046.

[0083] S1045, restore the alarm event to the root cause alarm, and match the alarm event with each saved secondary alarm one by one to determine whether there is a target secondary alarm that successfully matches the alarm event, and then convert the target secondary alarm into a cache event.

[0084] Among them, the target secondary alarm complies with the root cause rule corresponding to the alarm event.

[0085] For the root cause alarms that need to be restored, by matching with the saved secondary alarms, the convergence relationship between the root cause alarms and the secondary alarms can be automatically reconstructed.

[0086] S1046, restore the alarm event as a secondary alarm, or convert the alarm event into a cached event.

[0087] It will be understood that the type of the alarm event can be checked before restoration. If the alarm event has established a convergence relationship with the root cause alarm or has been saved as a secondary alarm, then the alarm event is restored as a secondary alarm. For another example, if the alarm event is still within the cached time window or has been saved as a cached alarm, then the alarm event is also restored as a cached event.

[0088] In some embodiments, it further includes: polling the cached events by using a timer; during the polling process: in response to the current cached time of the cached event exceeding the cached time window, converting the cached event into an abnormal event to wait for execution, where the cached time window is determined by the caching condition.

[0089] In some embodiments, it further includes: issuing a ticket for the root cause alarm; and issuing a ticket for the abnormal event.

[0090] Based on the above method, the service platform that executes the above alarm processing method can automatically issue tickets for abnormal events and root cause alarms, facilitating the operation and maintenance personnel to check the current fault situation faster and more accurately, and improving the efficiency of operation and maintenance management.

[0091] Figure 4 It is a schematic diagram 400 of an alarm processing device based on a custom rule provided exemplarily by the present application. As Figure 4 , the device includes a rule acquisition module 401 and an alarm convergence module 402; where:

[0092] The rule acquisition module 401 is configured to acquire a target alarm rule, where the target alarm rule is generated by a user's custom configuration for a target device to be monitored, and the target alarm rule includes: a root cause rule for identifying a root cause alarm and a secondary rule for identifying a secondary alarm, and the secondary rule has an associated item of the root cause rule;

[0093] The alarm convergence module 402 is used to obtain the alarm events occurring in the target device, identify the alarm events according to the root cause rules to determine whether they are root cause alarms; if so, save the alarm events as root cause alarms, extract the assignments of the associated items in the root cause alarms, and identify each cached event one by one according to the secondary rules and the assignments of the associated items to determine whether secondary alarms associated with the root cause alarms can be extracted from each cached event. The cached event refers to an event that meets the preset caching conditions and occurred earlier than the alarm event; otherwise, it is determined whether the alarm event is a secondary alarm according to the caching conditions.

[0094] As an example, the rule acquisition module 401 can be an interface operable by the user, such as an interactive front-end configuration interface. The alarm convergence module 402 can be a background server corresponding to the front-end configuration interface.

[0095] In some embodiments, the associated items include root cause association attributes, secondary association attributes, and comparison operators configured by the user;

[0096] Among them, the root cause association attribute refers to the alarm attribute configured by the user in the root cause rule, the secondary association attribute refers to the alarm attribute configured by the user in the secondary rule, and the comparison operator is used to indicate the convergence logic relationship that needs to be satisfied between the root cause association attribute and the secondary association attribute.

[0097] In some embodiments, to determine whether the alarm event is a secondary alarm according to the caching conditions, the alarm convergence module 402 is used for:

[0098] If the caching conditions are met, the alarm event is matched with each saved root cause alarm one by one to determine whether there is a target root cause alarm that matches the alarm event, where the alarm event conforms to the root cause rule corresponding to the target root cause alarm;

[0099] If so, save the alarm event as a secondary alarm associated with the target root cause alarm;

[0100] Otherwise, extract the assignments of the associated items in each saved root cause alarm and cache the assignments of the associated items in each saved root cause alarm;

[0101] If the caching conditions are not met, wait to execute the alarm event.

[0102] In some embodiments, the alarm convergence module 402 is further used for:

[0103] In response to the user's instruction to restore the alarm event, determine whether the alarm event is a root cause alarm;

[0104] If so, restore the alarm event to a root cause alarm, and match the alarm event with each saved secondary alarm one by one to determine whether there is a target secondary alarm that matches the alarm event successfully. Subsequently, convert the target secondary alarm into a cached event, where the target secondary alarm complies with the root cause rule corresponding to the alarm event.

[0105] Otherwise, restore the alarm event to a secondary alarm, or convert the alarm event into a cached event.

[0106] In some embodiments, the alarm convergence module 402 is further configured to:

[0107] Poll the cached events using a timer; during the polling process:

[0108] In response to the current cache time of the cached event exceeding the cache time window, convert the cached event into an exception event to wait for execution, where the cache time window is determined by the cache condition.

[0109] In some embodiments, the alarm convergence module 402 is further configured to:

[0110] Trigger an order for the root cause alarm; and trigger an order for the exception event.

[0111] Furthermore, as Figure 5 , an exemplary embodiment of the present application further provides an electronic device 500, including one or more memories 501 and one or more processors 502. One or more memories 501 are coupled to one or more processors 502 and store instructions thereon. The instructions can be executed by one or more processors 502 alone or jointly, so that the electronic device executes the method according to any one of the first aspect.

[0112] It should be understood that the processor mentioned in the embodiments of the present application may be a CPU, or may also be other general-purpose processors, DSPs, ASICs, FPGAs or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0113] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory, dynamic random access memory, synchronous dynamic random access memory, double data rate synchronous dynamic random access memory, enhanced synchronous dynamic random access memory, synchronous link dynamic random access memory, and direct memory bus random access memory.

[0114] The present application also provides a non-transitory computer-readable storage medium storing machine-executable instructions, which can be executed by one or more processors of a machine. The machine may include the electronic device mentioned above, etc. When the machine-executable instructions are executed by one or more processors, the machine is caused to execute any of the methods mentioned above.

[0115] The computer-readable storage medium may contain a propagated data signal having computer program code embodied therein, for example, on a baseband or as part of a carrier wave. The propagated signal may have various manifestations, including electromagnetic form, optical form, etc., or a suitable combination thereof. The computer-readable storage medium can be connected to an instruction execution system, apparatus, or device to effect communication, propagation, or transmission for use of the program. The program code located on the computer-readable storage medium can be propagated through any appropriate medium, including radio, cable, fiber optic cable, radio frequency signal, or similar media, or any combination of the above media.

[0116] The basic concepts have been described above. Obviously, for those skilled in the art, the above invention disclosure is only an example and does not constitute a limitation to the present application. Although not explicitly stated here, those skilled in the art may make various modifications, improvements, and corrections to the present application. Such modifications, improvements, and corrections are proposed in the present application, so such modifications, improvements, and corrections still fall within the spirit and scope of the exemplary embodiments of the present application.

[0117] Meanwhile, the present application uses specific terms to describe the embodiments of the present application. For example, "an embodiment", "one embodiment", and / or "some embodiments" mean a certain feature, structure, or characteristic related to at least one embodiment of the present application. Therefore, it should be emphasized and noted that the "one embodiment" or "an embodiment" or "an alternative embodiment" mentioned twice or more at different positions in this specification does not necessarily refer to the same embodiment. In addition, certain features, structures, or characteristics in one or more embodiments of the present application can be appropriately combined.

[0118] Some aspects of the present application can be executed entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. The above-mentioned hardware or software can all be referred to as "data blocks", "modules", "engines", "units", "components", or "systems". The processor can be one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DAPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, or a combination thereof. In addition, aspects of the present application may be embodied as a computer product located on one or more computer-readable media, which includes computer-readable program code. For example, the computer-readable media may include, but is not limited to, magnetic storage devices (such as hard disks, floppy disks, magnetic tapes...), optical discs (such as compact discs CD, digital versatile discs DVD...), smart cards, and flash memory devices (such as cards, sticks, key drives...).

[0119] The computer-readable media may contain a propagated data signal that contains computer program code, such as on a baseband or as part of a carrier wave. The propagated signal may have various forms of representation, including electromagnetic form, optical form, etc., or a suitable combination of forms. The computer-readable media can be any computer-readable media other than computer-readable storage media, which can be connected to an instruction execution system, apparatus, or device to implement communication, propagation, or transmission for use of the program. The program code located on the computer-readable media can be propagated through any suitable media, including radio, cable, fiber optic cable, radio frequency signal, or similar media, or any combination of the above media.

[0120] Similarly, it should be noted that, in order to simplify the description of the present application and thus help the understanding of one or more embodiments of the invention, in the foregoing description of the embodiments of the present application, sometimes multiple features are grouped into one embodiment, drawing, or description thereof. However, this disclosure method does not mean that the features required by the subject matter of the present application are more than those mentioned in the claims. In fact, the features of the embodiment are fewer than all the features of the single embodiment disclosed above.

[0121] In some embodiments, numbers are used to describe components and the quantity of attributes. It should be understood that such numbers used in the description of embodiments are, in some examples, modified by the modifiers "about", "approximately" or "substantially". Unless otherwise specified, "about", "approximately" or "substantially" indicate that the stated number allows a variation of ±20%. Accordingly, in some embodiments, the numerical parameters used in the specification and claims are approximate values, which may vary according to the characteristics required by individual embodiments. In some embodiments, the numerical parameters should consider the specified significant digits and adopt the method of retaining the general number of digits. Although the numerical ranges and parameters used in some embodiments of the present application to confirm the breadth of their scope are approximate values, in specific embodiments, such numerical settings are made as precise as possible within the feasible range.

[0122] Although the present application has been described with reference to the current specific embodiments, those of ordinary skill in the art should recognize that the above embodiments are only used to illustrate the present application, and various equivalent changes or substitutions can be made without departing from the spirit of the present application. Therefore, as long as the changes and modifications to the above embodiments are within the scope of the spirit of the present application, they will fall within the scope of the claims of the present application.< / ip> < / ip>

Claims

1. An alarm processing method based on custom rules, characterized in that Including: Obtain a target alarm rule, which is custom-configured by a user for a target device to be monitored. The target alarm rule includes: a root cause rule for identifying a root cause alarm and a secondary rule for identifying a secondary alarm, and the secondary rule has an associated item of the root cause rule; Obtain an alarm event that occurs on the target device, and identify the alarm event according to the root cause rule to determine whether it is the root cause alarm; If so, save the alarm event as the root cause alarm, extract the assignment of the associated item in the root cause alarm, and identify each cached event one by one according to the secondary rule and the assignment of the associated item to determine whether a secondary alarm associated with the root cause alarm can be extracted from the cached events, where the cached event refers to an event that meets a preset caching condition and occurs earlier than the alarm event; Otherwise, determine whether the alarm event is the secondary alarm according to the caching condition.

2. The method according to claim 1, wherein The associated item includes a root cause association attribute, a secondary association attribute, and a comparison operator configured by the user; Among them, the root cause association attribute refers to an alarm attribute configured by the user in the root cause rule, the secondary association attribute refers to an alarm attribute configured by the user in the secondary rule, and the comparison operator is used to indicate the convergence logic relationship that needs to be satisfied between the root cause association attribute and the secondary association attribute.

3. The method according to claim 2, characterized in that The determining whether the alarm event is the secondary alarm according to the caching condition includes: If the caching condition is met, match the alarm event with each saved root cause alarm one by one to determine whether there is a target root cause alarm that matches the alarm event successfully, where the alarm event conforms to the root cause rule corresponding to the target root cause alarm; If so, save the alarm event as the secondary alarm associated with the target root cause alarm; Otherwise, extract the assignment of the associated item in each saved root cause alarm and cache the assignment of the associated item in each saved root cause alarm; If the caching condition is not met, wait to execute the alarm event.

4. The method according to any one of claims 1-3, characterized in that, It further includes: In response to an instruction from the user to resume the alarm event, determine whether the alarm event is the root cause alarm; If so, resume the alarm event as the root cause alarm, and match the alarm event with each saved secondary alarm one by one to determine whether there is a target secondary alarm that matches the alarm event successfully, and then convert the target secondary alarm into the cached event, where the target secondary alarm conforms to the root cause rule corresponding to the alarm event; Otherwise, resume the alarm event as the secondary alarm, or convert the alarm event into the cached event.

5. The method according to claim 4, characterized in that, It further includes: Use a timer to poll the cached events; During the polling process: In response to the current caching time of the cached event exceeding the caching time window, convert the cached event into an abnormal event to wait for execution, where the caching time window is determined by the caching condition.

6. The method according to claim 5, characterized in that, It further includes: Create a work order for the root cause alarm; And, Create a work order for the abnormal event.

7. An alarm processing device based on custom rules, characterized in that, Including: A rule acquisition module for acquiring target alarm rules, where the target alarm rules are custom-configured by a user for target devices to be monitored, and the target alarm rules include: a root cause rule for identifying root cause alarms and a secondary rule for identifying secondary alarms, and the secondary rule has an associated item of the root cause rule; An alarm convergence module for acquiring alarm events occurring in the target device, identifying the alarm events according to the root cause rule to determine whether they are root cause alarms; if so, saving the alarm events as the root cause alarms, extracting the assignments of the associated items in the root cause alarms, and identifying each cached event one by one according to the secondary rule and the assignments of the associated items to determine whether secondary alarms associated with the root cause alarms can be extracted from the cached events, where the cached events refer to events that meet preset cache conditions and occur earlier than the alarm events; otherwise, determining whether the alarm events are secondary alarms according to the cache conditions.

8. An electronic device, comprising: One or more processors; And One or more memories coupled to the one or more processors and storing instructions thereon, which when executed by the one or more processors alone or in combination, cause the electronic device to execute the method according to any one of claims 1-6.

9. A non-transitory computer-readable storage medium storing machine-executable instructions, which when executed by one or more processors of a machine, cause the machine to execute the method according to any one of claims 1-6.

10. A computer program product comprising machine-executable instructions, which when executed by one or more processors of a machine, cause the machine to execute the method according to any one of claims 1-6.